contract-intelligence-workflow-reviewer-carl-ditzler

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs workspace initialization by executing an internal Python script that copies template files to a local directory. This process is transparent and limited to setting up the intended workflow environment.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the ingestion of contract documents via user-provided links and cloud storage connectors. These operations are essential for the skill's function and are managed through a security framework that defaults to minimal access and requires user confirmation.
  • [PROMPT_INJECTION]: The skill addresses indirect prompt injection risks associated with processing external documents through mandatory structured parsing, context window management, and specialized failure-mode checks designed to detect adversarial clauses. Ingestion occurs via the intake form, and the skill mitigates risks through structural clause parsing and mandatory failure-mode sweeps.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:33 PM
Security Audit — agent-trust-hub — contract-intelligence-workflow-reviewer-carl-ditzler